HeaderCheck
Privacy Policy
Effective September 5, 2026
HeaderCheck (“the App”) is a privacy-first iOS and iPadOS application that analyzes email authentication headers (SPF, DKIM, and DMARC) entirely on your device from pasted text or an .eml file.
Summary
Analysis stays on your device. HeaderCheck does not require an account, does not sign you in, and does not upload headers, message content, or identifiers to a server operated by the developer. There are no analytics or tracking SDKs in the App.
Information the App processes
When you paste headers or open an .eml file, the App processes that content locally to show authentication verdicts, alignment hints, and cautious heuristic flags. That content is not transmitted to the developer for analysis.
Information stored on your device
If you save analyses to History (subject to free limits, or unlimited with Pro), they are stored locally on your device using Apple’s on-device storage (SwiftData). Deleting the App removes that local data, subject to any backups you manage yourself (for example iCloud device backups controlled by Apple and your settings).
Purchases
Optional HeaderCheck Pro is a one-time In-App Purchase processed by Apple through StoreKit. Payment card details are handled by Apple; the developer does not receive your payment card information. Apple’s privacy practices apply to the App Store and purchase processing.
No developer-operated tracking
The App does not include third-party analytics, advertising, or crash reporting SDKs that send usage data to the developer. Network access is not required for core analysis.
Disclaimer
HeaderCheck reports authentication results found in the headers you provide. It does not guarantee that a message is safe or malicious, and it is not legal or forensic advice.
Contact
Privacy questions about HeaderCheck: HeaderCheck@mclarty.me.
Changes
If this policy changes, the updated text will be posted at this URL with a revised effective date.